Edit: /etc/apparmor.d/linux-sandbox (383B)
# This profile allows everything and only exists to give the
# application a name instead of having the label "unconfined"
abi
,
include
profile linux-sandbox /usr/libexec/@{multiarch}/bazel/linux-sandbox flags=(unconfined) {
userns,
# Site-specific additions and overrides. See local/README for details.
include if exists
}